Vulnerabilities > CVE-2004-2569 - Symbolic Link vulnerability in IPMenu Log File

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
david-stes
nessus

Summary

ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack on the ipmenu.log temporary file.

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-907.NASL
descriptionAkira Yoshiyama noticed that ipmenu, an cursel iptables/iproute2 GUI, creates a temporary file in an insecure fashion allowing a local attacker to overwrite arbitrary files utilising a symlink attack.
last seen2020-06-01
modified2020-06-02
plugin id22773
published2006-10-14
reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/22773
titleDebian DSA-907-1 : ipmenu - insecure temporary file